CVE

Id
64740  
CVE No.
CVE-2013-4793  
Status
Candidate  
Description
The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require authentication, which allows remote attackers to execute arbitrary ASP.NET code via a crafted SOAP request.  
Phase
Assigned (20130712)  
Votes
None (candidate not yet proposed)  
Comments